> For the complete documentation index, see [llms.txt](https://copilot-docs.bugbase.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://copilot-docs.bugbase.ai/enterprise/attack-surface/target-assets.md).

# Target Assets

Target Assets manages external root targets. Assessment wizards select existing scope; they do not provide a general-purpose target-creation form.

## External Domains

Add root domains only, such as `example.com`. Do not add a scheme, path, or query string. Subdomains and paths are discovered later.

From **External Assessment -> Run Assessment -> Scope**, use **Manage target assets** when the required root domain is missing. After adding it:

1. confirm it is allowed by **Settings -> Domains**;
2. complete ownership verification when required;
3. return to Scope and select it.

The target row shows verification and whitelist state.

## Other Assessment Scope

* **Internal subnets** come from the reachable subnet inventory reported by the selected agent.
* **Cloud scopes** are created by cloud discovery from the workload identity attached to the selected agent.
* **Code repositories** come from the connected GitHub App installation.
* **APK files** use their dedicated upload workflow when mobile analysis is enabled.

Select discovered internal or cloud targets from **Internal Assessment -> Run Assessment -> Scope**. Select code repositories and their branch, PR, tag, or commit from **Code Assessment -> Run Assessment -> Scope**.

## Deleting or Changing External Targets

Before deleting a target, check whether schedules, reports, attack paths, browser sessions, or graph data still depend on it. Update **Settings -> Domains** and **Settings -> Trajectories** when the approved external scope changes.
